Files
dotfiles/modules/profiles/README.md
T
2026-09-10 14:50:54 +09:00

105 lines
6.6 KiB
Markdown

# Profiles
Profiles are host-selectable compositions of independently owned units. They
describe why a group of units is enabled; application, service, system, and
hardware configuration remains in its owning unit.
## Layers
| Namespace | Purpose | Compatibility |
| ------------ | ------------------------------------------------------- | --------------- |
| `base` | Invariants required by every host | NixOS and macOS |
| `interface` | Command-line and graphical ways to operate a host | Per-profile |
| `platform` | NixOS foundation and physical or virtual hardware shape | NixOS |
| `workload` | Optional activities performed on a host | Per-profile |
| `networking` | Network roles and topology | Per-profile |
| `security` | Optional security and secret-management policies | Per-profile |
`base` contains the shared Nix foundation plus the universally available CLI
tools (Atuin, tealdeer, trippy, and xh). A unit belongs there only when it is
required on every supported host.
## Compatibility
| Profile | Supported host class |
| ------------------------------------ | --------------------------------------------- |
| `base` | NixOS, macOS |
| `interface.minimal` | NixOS, macOS with Home Manager |
| `interface.cli` | NixOS, macOS with Home Manager |
| `interface.gui` | NixOS, macOS with Home Manager |
| `interface.macos` | macOS |
| `interface.linux-desktop` | NixOS with Home Manager |
| `interface.labwc` | NixOS with Home Manager |
| `interface.niri` | NixOS with Home Manager |
| `platform.nixos` | NixOS |
| `platform.desktop` | Physical NixOS desktop |
| `platform.intel-nvidia-desktop` | Intel/NVIDIA physical NixOS desktop |
| `platform.laptop` | Physical NixOS laptop |
| `platform.thinkpad-x1` | Intel ThinkPad X1 running NixOS |
| `platform.vm` | UEFI QEMU NixOS guest with NFS client support |
| `workload.deploy-rs-target` | NixOS |
| `workload.development` | NixOS, macOS with Home Manager |
| `workload.game` | NixOS, macOS |
| `workload.machine-learning` | NixOS with Home Manager |
| `workload.personal` | NixOS, macOS with Home Manager |
| `workload.photography` | NixOS with Home Manager |
| `workload.remote-access` | NixOS, macOS |
| `workload.camera` | NixOS |
| `workload.server` | NixOS, macOS with Home Manager |
| `networking.tailscale-client` | NixOS, macOS |
| `networking.tailscale-subnet-router` | NixOS |
| `security.fingerprint` | NixOS, macOS |
| `security.secrets` | NixOS, macOS |
| `security.secure-boot` | NixOS |
| `security.tpm-storage` | NixOS with a host-defined LUKS device |
Select independent concerns independently in `hosts/default.nix`. For example,
a NixOS desktop can combine `interface.labwc` and `interface.niri` to provide
both sessions while sharing `interface.linux-desktop` and `interface.gui`.
The shared Linux desktop profile provides the common desktop applications and
session-independent services; both session profiles select ly. The laptop
platform selects niri as Ly's default session, while the desktop platform
selects labwc. A daily-use macOS development machine can combine
`interface.macos`, `workload.development`, and `workload.personal`. Hardware
support does not implicitly select an interface or workload.
`platform.nixos` selects the shared network foundation and the clatd service.
VM, laptop, and desktop platform profiles inherit both.
`interface.minimal` provides SSH client access and key generation, Nano, htop,
btop, fastfetch, unzip, wget, Direnv, Git, GnuPG, nh, Zellij, and Zsh for remote
administration. `interface.cli` includes that baseline and adds the configured
Neovim, Yazi, and the remaining interactive command-line tools.
`workload.machine-learning` provides the Hugging Face Hub CLI for hosts used
to download and publish machine learning models and datasets.
`workload.photography` provides darktable with AI support from the locked
unstable package set. Its ONNX Runtime uses CUDA when the NVIDIA hardware unit
is enabled, and CPU inference otherwise. Keep the default CUDA capabilities
and forward compatibility to reuse the CUDA binary cache; these targets include
galleria's RTX 3060 Ti. OpenCL drivers remain owned by hardware units.
`workload.deploy-rs-target` enables OpenSSH and provisions the `nixdeploy`
service account with the narrowly scoped passwordless commands required for
deploy-rs activation and rollback confirmation.
`workload.personal` provides Pear Desktop on both NixOS and macOS. Home Manager
enables performance improvements, synced lyrics, tracker blocking, the album
color theme, and custom output-device selection while preserving user-owned
settings such as the selected device.
`workload.personal` provides ActivityWatch for local activity tracking. On
NixOS, its server and Wayland-compatible watcher run as Home Manager user
services. On macOS, the Homebrew cask starts at login.
On NixOS, `workload.game` provides Steam with Valve Proton and Proton-GE,
Protontricks, Wayland-compatible Steam Input, GameMode, Gamescope, and MangoHud.
Enabling Steam also activates the 32-bit graphics and PipeWire support required
by older games. On macOS the same profile currently provides the portable game
applications that support that host class.
`security.tpm-storage` deliberately does not own a disk identifier. A host that
selects it must define `boot.initrd.luks.devices.cryptroot.device` in its
machine-specific NixOS module.